Carder.su was a large Russian-run, internet-based transnational cybercriminal enterprise centered on carding, identity theft, and financial fraud. It operated from at least 2005 through 2011 as a structured online marketplace and forum ecosystem used by thousands of members to traffic in compromised payment card data, counterfeit payment cards, counterfeit identification documents, and related fraud services. Known aliases and related forum brands included Carder.su and the Carder.su organization, with associated forums such as Carder.info, Crdsu.su, Carder.biz, and Carder.pro. The organization maintained defined roles including administrators, moderators, reviewers, vendors, and general members, and used vetting procedures for new entrants, including member sponsorship, to reduce infiltration. Its infrastructure and operational security practices emphasized anonymity and resilience, including use of encrypted or private communications, proxies, VPNs, and protected drop mechanisms. The group also relied on specialized service providers such as counterfeit document producers, sellers of stolen payment card data, counterfeit card manufacturers, cashout providers, and bulletproof hosting operators. Carder.su’s core criminal activity involved trafficking stolen credit and debit card data, producing and distributing counterfeit cards and false identification documents, identity theft, bank fraud, and other computer-enabled financial crimes. Members also exchanged fraud tradecraft and enabled downstream cashout operations. Reporting tied the broader enterprise to large-scale victim losses and described additional criminal activity by associated members including money laundering, narcotics trafficking, and other computer crime. Operation Open Market, a long-running undercover law-enforcement investigation, led to dozens of indictments and convictions connected to the enterprise. Publicly identified participants included figures such as Roman Seleznev, David Ray Camez, Alexander Kostyukov, Maceo Boozer III, Edward Montecalvo, Jermaine Smith, Makai Haggerty, and Qasir Mukhtar, among others. Carder.su is best understood as a mature cybercrime forum and criminal marketplace whose dominant purpose was financially motivated payment-card fraud and identity-related crime rather than espionage or disruptive operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An international cybercriminal enterprise focused on trafficking stolen credit card data and counterfeit identifications, and conducting identity theft, bank fraud, and computer crimes.
Russian-run cybercriminal enterprise operating the Carder.su forum for trafficking compromised credit card data, counterfeit credit cards, fake IDs, and sharing fraud schemes.
A sophisticated cybercrime organization that operated a worldwide online marketplace and forum for stolen personal and financial information, counterfeit credit cards, fraud services, and related criminal activity including money laundering and narcotics trafficking.
A criminal carding enterprise operating online forums and marketplaces for identity theft, counterfeit identification documents, stolen payment card data, device-making equipment, and related financial fraud.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.